CVE-2024-8970: Incorrect Authorization in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8970?
CVE-2024-8970 has been classified as a moderate severity vulnerability.
What versions of GitLab are affected by CVE-2024-8970?
CVE-2024-8970 affects GitLab versions from 11.6 to 17.2.9, from 17.3 to 17.3.5, and from 17.4 to 17.4.2.
How do I fix CVE-2024-8970?
To fix CVE-2024-8970, upgrade your GitLab instance to version 17.2.9 or later, 17.3.5 or later, or 17.4.2 or later.
What type of attack is possible with CVE-2024-8970?
CVE-2024-8970 allows an attacker to trigger a pipeline as another user under certain circumstances.
Can CVE-2024-8970 be exploited without authentication?
Exploitation of CVE-2024-8970 may require certain conditions but does not explicitly state that authentication is bypassed.